mariana-outlook-mcp
Gives Claude Code access to Outlook Mail, Calendar, and Contacts via Microsoft Graph, with safety-first defaults (no sending, no hard deletes, every mutation logged). Supports multiple Microsoft accounts through a PKCE OAuth flow.
README
mariana-outlook-mcp
A custom MCP (Model Context Protocol) server that gives Claude Code access to Outlook Mail, Calendar, and Contacts via Microsoft Graph — with safety-first defaults. Sibling of mariana-google-mcp, same architecture pointed at Microsoft accounts (M365 work/school and personal Outlook/Hotmail).
Design Philosophy
Built for an operator who wants AI help managing their mailbox without risk of accidental damage:
- No sending email — enforced by Microsoft, not just this code. The server never requests the
Mail.Sendpermission, so its tokens are physically incapable of sending. You draft; you send from Outlook. - No deleting anything. Mail moves to a "To Be Deleted" folder (reversible). Calendar events get "DELETE - " prepended to the title. You review and confirm in the Outlook UI.
- Every mutation is logged. An append-only JSONL action log records every write with timestamps, tool name, account, and summary.
- Multi-account support. Work and personal Microsoft accounts under named aliases.
- No client secret. Desktop PKCE flow — the only credential is a public Application ID.
Setup
Easiest path: paste this one line into Claude Code and it runs the entire setup for you, including guiding you through the Azure clicks:
Fetch https://raw.githubusercontent.com/marianasmall/mariana-outlook-mcp/main/SETUP-PROMPT.md and follow the instructions in it.
The manual steps below cover the same ground.
1. Azure App Registration
- Go to portal.azure.com → search "App registrations" → New registration
- Name: "Claude Code". Supported account types: Accounts in any organizational directory and personal Microsoft accounts (the option that includes personal accounts)
- Redirect URI: platform Public client/native (mobile & desktop), value
http://localhost - Register, then copy the Application (client) ID from the Overview page
- Under Authentication, set "Allow public client flows" to Yes
No client secret is created — this is a PKCE public client.
2. Install and Build
git clone https://github.com/marianasmall/mariana-outlook-mcp.git
cd mariana-outlook-mcp
npm install
npm run build
3. Add to Claude Code
claude mcp add outlook --scope user \
-e MS_CLIENT_ID="<application-client-id>" \
-- node /FULL/PATH/TO/mariana-outlook-mcp/dist/index.js
Optional: set MS_TENANT to a specific tenant ID (defaults to common, which accepts both work and personal accounts). Restart Claude Code after adding.
4. Authenticate
Run the microsoft_auth tool with a friendly account name (e.g. consulting, personal). A browser window opens for consent; approve as the matching Microsoft account. Repeat per account. Verify with microsoft_status.
Available Tools (20)
Authentication & Status
| Tool | Description |
|---|---|
microsoft_auth |
Authenticate a Microsoft account via OAuth browser flow (PKCE) |
microsoft_status |
Live connection health for all configured accounts |
Mail (10 tools)
| Tool | Description |
|---|---|
outlook_search |
Search messages (KQL: from:, subject:, or keywords) |
outlook_read |
Read a specific message by ID (plain-text body + attachment names) |
outlook_draft |
Create a draft — plain text or rich HTML body, attachments (≤3MB/file), optional reply-in-thread (does NOT send) |
outlook_list_folders |
List mail folders with unread counts |
outlook_list_categories |
List categories (the Gmail-labels equivalent) |
outlook_create_category |
Create a category |
outlook_apply_category |
Apply a category to messages |
outlook_remove_category |
Remove a category from messages |
outlook_create_rule |
Create an inbox rule (the Gmail-filter equivalent) |
outlook_move_to_delete |
Soft-delete: move messages to a "To Be Deleted" folder |
Calendar (7 tools)
| Tool | Description |
|---|---|
calendar_list |
List upcoming events |
calendar_search |
Search events by title keyword |
calendar_get |
Full details of one event |
calendar_create |
Create an event (attendees NOT invited by default) |
calendar_update |
Modify an event (attendee-notification caveat in tool description) |
calendar_flag_delete |
Soft-delete: prepend "DELETE - " to the title |
calendar_availability |
Free/busy blocks for a date range |
Contacts (2 tools)
| Tool | Description |
|---|---|
contacts_search |
Search contacts by name, email, or phone |
contacts_list |
List contacts, optionally filtered |
Multi-Account Support
microsoft_auth account_name: "consulting"
microsoft_auth account_name: "personal"
Most tools accept an optional account parameter; omitted, they use the default (first-connected) account. microsoft_status shows all accounts and their health.
Configuration Files
All state lives in ~/.config/mariana-outlook-mcp/:
| File | Purpose |
|---|---|
config.json |
Account registry (aliases, email hashes, default) |
tokens/<hash>.json |
OAuth tokens per account (never leave this machine) |
action-log.jsonl |
Append-only log of every write operation |
Graph-vs-Gmail Differences Worth Knowing
- Categories ≈ labels; folders ≈ folders. Outlook has both. Categories apply like Gmail labels; soft-delete uses a folder because that's the native Outlook idiom.
- Reply drafts take a
reply_to_message_id(Graph threads replies from a message, not a thread ID). - Moved messages get new IDs — Graph reassigns message IDs on folder moves.
- Attendee invitations: Outlook sends invitation/update emails itself when an event has attendees;
calendar_createtherefore defaults to NOT attaching attendees (names go in the description) unlesssend_invites=true. - Refresh tokens last ~90 days sliding for personal accounts — regular use keeps them alive indefinitely; a long-unused account may need re-auth.
License
MIT
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。